Privacy is at a crossroads. Choose wisely
medium.com
medium.com
However, every time I use DDG it hurts a bit. The quality of the results are very far behind from that of Google's. I many times end up doing a Google search in incognito mode because DDG just doesn't cut it. I hope DDG improves, because I haven't seen that improvement during the past year.
But I'll keep an eye out and actually write down particular queries where I see these phenomena, and send them along.
I agree with your chagrin at the loss of the plus symbol.
I do the same search on Google and it gives me links to Currys, Tesco, Argos and Maplin (all UK shops/sites). And it links me to Amazon.CO.UK and Ebay.CO.UK.
I don't use DuckDuckGo for searching for products which I want to buy, because this is always what happens.
I suspect DuckDuckGo is a much better search experience for people inside the US than outside.
EDIT: Ooh. I've just noticed that if I set my region to "UK" in DuckDuckGo the results suddenly become far more relevant. Why isn't this set by default? Not only am I coming from a UK IP address, but my browser is sending "Accept-Language: en-gb"
As far as I can tell, Google will always tell you when it thinks you made a mistake, and provide a link to search for your exact query.
Lack of date-bounded search is a frequent reason to resort to Google. Special collections (Scholar, Books, News) others.
I'm actually relying far more on DDG image search than even a few months ago -- the results are getting good. Also the instant answers, which are getting good.
There have been a few times in recent past where DDG searches have turned up empty (or unsatisfactory results) while Google's nailed it. Actually went hunting for an example and got lost which is why this comment is so late. Couldn't find the example though I'll try to remember to submit it when I do.
The sample is only searches where DDG fails; inevitably, every other search engine will provide better results.
(That doesn't mean DDG is better or worse than Google; it only means that this methodology doesn't provide infromation on that topic.)
The sample is only searches where DDG fails; inevitably,
every other search engine will provide better results.
That's not guaranteed. You could try the search on Google in an incognito tab and decide you think the results are actually worse.(But yes, it is a skewed sample.)
80% searches work flawlessly on ddg, and for the remaining part you learn which kind of searches that will work and which ones doesn't. Many times i know in advance that this particular query will probably not work here but on google it will and i'll just append !g to the search to go straight to google.
What i find mostly interesting is that I have re-learned to use multiple different search engines, you know like we all did back before in the days, and that it actually helps me find more relevant information. Not only because the quality of Google has dropped significantly the past 5 years but even when google delivers a pretty solid result i check DDG after and i might find an even more relevant result, or an opposing story in a political topic etc. We all learn to check your information sources, this includes your search engine!
If that's the only difference, isn't Google-over-Tor a better option? Known privacy with world-class search results?
They set and read no cookies. You can test this yourself.
They set etags on static assets, and those theoretically could be used to track you as an identifiable visitor.
How else would they track you? By IP address? That would make any kind of tracking useless -- how would you deal with trying to track 100,000 connections from behind NAT, individually, other than cookies or etags?
There's browser fingerprinting, but I don't see any evidence of that either.
No, DDG is better because they don't limit or captcha you over Tor.
Also, brand names do matter. If DDG has staked their reputation on privacy, it's a safer bet. It would be difficult for them to be monetizing personal data when it's their stated policy not to. You'd have to hope the people you're selling this data to keep their mouths shut and so do DDG (ex)employees.
For example, if you search for "python", it would have to guess whether you are a programmer, or a biologist, in order to present the most relevant results. And of course, Google already has all this information...
Example of what I meant: https://duckduckgo.com/?q=BMW+723i
Seriously, quoting that is a reasonable solution. Given the comparative popularity of the two, it seems statistically likely that most people actually wanted a 323i. Having said that, I note that Google doesn't show 323i results for 723i, so... hm.
I do think explaining the substitution that was done and linking to the exact search (ie, how Google does it) would be a good feature though.
That's over-guessing.
In the mean time for general searches, I either use DDG's results or slap on a pre-emptive !g on a hunch, randomly or just-in-case. My idea behind this is that, as DDG's results become better, I'll habitually start using !g less and less.
And indeed, DDG's results have become better, and indeed I have been using the !g command less and less.
Google Search with !g is slowly becoming "just another one among the predefined !bang commands", a command I will append after my searches when I specifically desire to find out what Google has to say about a certain query. Though in comparison I hardly ever use !y and !b (Yahoo and Bing, respectively), mostly because I have no clue in what vague sense those results would be better (with DDG vs Google, I sort of have a feeling when asking for something really mundane and stupid, Google always hits the spot exactly, DDG sometimes misinterprets--though less so lately).
For image searching I really use !yi, !bi and !gi pretty much randomly. They all give quite different results, but as far as I've been able to determine, none of them are of particularly better quality than the others. Yahoo Image Search has a nice integration with Flickr though, so I tend to use it more when my target may be found between high-ish resolution photography.
I already named !wayback, anyone got any other cool !bang commands they use often? For instance, any good documentation searches for JS/DOM/HTML/CSS etc? I tried !mdn but I don't like their search result pages. Same for !python, if I do "!python itertools", I want to be taken straight to the itertools module documentation, not a results page of all python docs that contains the term "itertools".
They claim to be "the world's most private search engine: https://ixquick.com/eng/protect-privacy.html?
Since this is a quote from the article, I feel this is an appropriate space to ask: does anyone have a page explaining how these various privacy extensions interact/overlap with each other? I tend to install (or at least try out) pretty much every popular one at some point or another, and I'm hoping to reduce redundancies. Alot of these tools show up on recommended "Get These If You're Serious About Privacy" lists without indicating what exactly each extension does or how it might interact with another extension. These include:
- Adblock Plus - Ghostery - Disconnect - HTTPS Everywhere - EFF Privacy Badger - uBlock - NoScript
At this point, I've "slimmed" down to just HTTPS Everywhere and uBlock, although I'm debating adding Privacy Badger. However, their own page mentions that it's "based on ABP code" [0], so my thought is that uBlock is probably also taking care of it.
Is that sufficient? Is there any danger in installing Privacy Badger and uBlock, for instance, if they serve the same function? Will they step on each other's toes?
Some kind of comparison chart would be useful.
For reference, I use: http://someonewhocares.org/hosts/
For those sites, opening up the site in incognito mode (which is by default sandboxed from any plugins) fixes them. A hostfile blacklist would require far more work to fix the jank.
"For the Firefox version of Privacy Badger, we also eschewed the ABP engine in favor of something we wrote ourselves. Don't get me wrong, ABP is a great tool and we learned a lot from its code - but we wanted something as lean and performant as possible....."
https://news.ycombinator.com/item?id=7686396
also ublock makes ABP, Ghostery & Disconnect redundant. https://github.com/gorhill/uBlock/wiki/%C2%B5Block-and-other...
Warning! When combined with other cookie monitoring addons such as Beef Taco, Cookie Monster, and Google Opt-Out, this feature can cause unresponsive script errors. If you experience this error, please try disabling this feature or conflicting addons.
(That analogy isn't perfect because the TSRs also had an issue about patching the interrupt descriptor table, which is where the system looks up the location of an interrupt handler; one common problem was that if TSRs weren't unloaded in the same order in which they were loaded, the table could be "restored" with values that were not actually current, which I don't think is a problem that has an equivalent for browser extensions!)
On one hand, it's cumbersome, requiring you to whitelist some requests and reload when you visit a new webpage (most sites require a CDN at least). On the other, it's easy to use and good security.
Couple of other related items just from today indicate this _may_ be taking on steam but we've seen this kind of blip before just to see it fade.
1. Helping Prove Mr. Weinberg's going (CEO of DuckDuckGo) is an article on how heath web sites share your search queries with 3rd parties found at http://motherboard.vice.com/read/looking-up-symptoms-online-... Nice to know that WebMD et al are sharing your _assumed_ private searched for whatever itch you might have with others.
2. Symantec published results of their European survey on the topic of Data Privacy found at http://www.symantec.com/content/en/us/about/presskits/b-stat... Not sure I believe a survey where the respondents claim to read the terms of service 25% of the time.... My guess would have been .25% of the time.
For anyone looking for health information (in English), I recommend the NHS website. (Start your search from there rather than Google if you're worried about being tracked). It may not be the best-looking website, but the info is written by medical professionals and there are no commercial interests since the NHS is funded by the UK taxpayer.
They have an A-Z of conditions, a symptom checker, videos and much more. (I presume this is all available to anyone outside the UK)
The NHS site you linked makes requests to google analytics, webtrends and cloudfront. The point in the parents article applies here equally, since what i'm searching will still be analyzed by Google at the very least.
I'm not sure how identifiable this information is though, but definitely important to be aware of
*Really, they'll even trade it for intangible gold. http://candycrushgametactics.com/get-free-gold-bars-in-candy...
There's always a subset of people who don't care. There was a time when women didn't have the right to vote, and although I wasn't around during that time, I'm sure there was a subset of women who didn't care. Their apathy is not a justification for withholding that right from the rest.
The problem is when it's the seeming majority who don't care.
They want privacy too, but one could argue that we've failed to educate them about how to use existing tools and failed to make those tools simple enough that they're usable by the average Joe.
Really? In my circles, even when I lived in "red" states, the attitude was more like it's a damn shame it's illegal, and too bad there isn't a prayer of it changing.
How about gay, women or minority rights. All of them were strongly opposed by the masses.
In the 1st and 3rd case, of course, because the subject group was a minority. In the case of women, things only changed when enough of the subject group started to demand change. In the case of privacy, the subject group isn't distinct from the masses, it is everyone. So yes, it's a problem for progress until everyone gets more clued in. (It will happen, when enough bad stuff has happened.)
Let's say google offers some kind of privacy plan, which is 100% outside of their interests. Do you think they'll give me honest pricing if I opted out of all their tracking? Lets say they actually make $15 off me annually via tracking. What would they charge me to not be spied on? It sure as hell won't be $15.
The problem is we're not being offered a fair value in the beginning when we get into a relationship with these companies. Cloud providers are throwing snickers bars at me and not offering to stop. When I do say I don't want them, I'm hit with punitive pricing. Look at AT&T's gigapower charge to not be spied on. Its like $40 a month. Sorry, but I doubt anyone is making $40 a month from someone like me who almost never clicks on ads and whose information can't be that valuable. If advertisers are paying AT&T $40 a month to see how long I'm on reddit, then the whole system is well... fucked.
It seems to me that cloud providers and ISPs want their cake and to eat it to. They're double-dipping. I'm still paying somehow, even if its indirectly. I bought $100 worth of apps and movie rentals last quarter via my android device. They sure as hell weren't free. Not only am I subject to market pricing on these items, not to mention my hefty phone bill, I also am being spied on? Where exactly is the 'free' where the products monetize themselves via app store purchases and rentals? VUDU and On Demand charge the exact same amount for these rentals.
This narrative that customers won't pay for things is asinine. We're constantly paying for things.
Sure, pricing will probably be set way too high by the companies at first, but even making that explicit tradeoff and the option to purchase will help show consumers that privacy IS valuable.
Addition parameters that would be interesting: Inform that the information is worth more/less than the Snickers bar, or inform that "the government" will have free access to the information.
Not as cheap as a Snickers, but I once had a CS professor do a straw poll of the class for this experiment. Back in the day the most evident tracking was through customer loyalty cards at grocery stores. He asked the class: how much money do you save per visit using your loyalty card? $10? And would you instead pay $10 each time to not be tracked?
Perhaps not surprisingly, in 2007 a room full of undergrads would take the discount.
Coordination problems. Coordination problems as far as the eye can see.
Compartments are isolated in VMs, with separate network connectivity using nested chains of VPNs, JonDonym and Tor. Particularly sensitive compartments are isolated in separate computers. It's prudent to avoid cross-compartment sharing of USB drives.
Excellent! There are a lot of historical precedents for technology enabling intermediation! Such intermediation comes with power, which does need to be tempered with some regulation. (The minimum possible, due to regulatory capture, of course.)
In other words, there are good and bad ways to use user data, some of the good ones are provably private, and we shouldn't rule out all data sharing as inherently evil.
Furthermore, even if a company was using differential privacy to anonymize data between the collection and the processing step, there is no way to prove that the data is being handled appropriately before and during the collection step. Also, there is no way for a company to prove that they continue to handle data appropriately over time.
These tools are super useful for releasing data sets to the public from a trusted source (such as a healthcare provider assisting researchers by releasing cancer data), but that's not what we're talking about here.
LeapYear Innovations [1] looks like they have some clients who care about differential privacy. [2]
You also didn't respond to this:
> Furthermore, even if a company was using differential privacy to anonymize data between the collection and the processing step, there is no way to prove that the data is being handled appropriately before and during the collection step. Also, there is no way for a company to prove that they continue to handle data appropriately over time.
Any company using shroudbase can choose to stop using shroudbase at any time, or accidentally introduce a bug into their collection method, or start also saving the data in MySQL at collection time.
Tools like that are useful to distribute data from trusted to non-trusted parties. You still have to trust the analytics and advertising companies doing the collection.
I agree. However, that's going to be the knee-jerk reaction for a while precisely because huge entities like Google, NSA, AT&T, Verizon, etc have been doing that data sharing while doing an abysmal job of notifying users about what was happening. Eventually I think we'll settle into a happy medium, but we're in the pushback phase at the moment.
citation?
They define the mathematical guarantees on privacy, which are computational guarantees against a polynomial-time adversary trying to distinguish between the analyses of two databases that differ in a single record. I.e., nobody can reasonably tell whether your information is included in the analysis.
I still would prefer a choice in the matter - a required small check box that says "record my data" or "do not record my data" XOR "erase my data". The term 'reasonably' has a very different meaning to me (assuming many unknowns in the future) over the long term.
It is either that, or people should literally stop making such a hard line distinguishing person A from person B. If the data is going to be used to make an inference from the collective to the individual, and it doesn't matter whether my data is included or not, well, shrug and thumbs up. It really depends on the context of the application. Does it determine whether my imaginary future children get to go to college or not?
The problem with data and private organizations is that we do not know what the data analysis is being used for, and as private citizens we do not have any control over how that data is mathematically reasoned about and qualitatively assessed aside from forging the data itself it (garbage in, garbage out).
And I misspoke about polynomial time adversaries. Reading closer it looks like an information theoretic guarantee.
I prefer to avoid living my life in a fishbowl.
> provably private
This does not have a mathematics definition. Private means not accessible to anyone aside from the owner. That is something that is provably private.
> information theoretic guarantee
This sounds like hand waving to get rid of actual concerns.
If I was actually typing out the opinions of my spouse word for word: whose age combined with my own is divisible by 3, how would that change your view?
In order for the data to be of any use, someone (be it the user or a trusted friend) has to be able to decrypt it. But if you (or your friend) can decrypt it, a hacker can also decrypt it. Hopefully, the hacker will find it more difficult without knowing the key. But the one in a million chance that he'll crack it on the first try exists by necessity.Even titanium breaks under stress.
In the pathological case that there's zero possibility (not even epsilon), the whole business of encryption is rendered moot because the rightful user himself cannot access the data! This means one of two things: the data is corrupt; or the data has been deleted entirely.
http://en.m.wikipedia.org/wiki/Information_flow_%28informati...
Obama has proven himself to be a warmonger with loose ethics unwilling to prosecute torture and also fully interested in continuing the surveillance state, killing Americans without due process, prosecuting whistle-blowers, and protecting the status quo above the constitution and civil rights.
This requires an attitude adjustment and significant tolerance because everything is public.
Want to know if your bank treats customers good or bad? Look it up. Want to know if the issuer bets against a mortgage backed security? Audit the numbers. Want to cheat on your taxes? Tough luck!
The thing is, we only have two options:
1. Only spooks and marketers and those who pay, know.
2. We all know.
http://mind.ucsd.edu/syllabi/98-99/logic/falsedichotomy.html
The post makes sense, DDG makes sense, good timing, ok no news to most of us but a good way to get people again talking about DDG.
Considering that DDG is 'just' a Yandex whitelabel (before Bing) with some extra features, especially the no tracking, it's surprising how big it got with Weinberg's Marketing hacks. Congrats!
No new consumer oriented web product in their right mind would advertise "we monetize your data with third parties", but they all include language in their Privacy Policies about sharing "partially anonymize" data. It might make you feel safe and sound when it comes to Company X protecting your identity, but marketers and other organizations don't look at data points in a vacuum, everything is in aggregate, and your aggregate profile represents you to the highest degree of certainty.
Incidentally, that's part of the reason why I'm having this feeling, that the future is a choice - "privacy or progress, pick one". Because if you really, really care about privacy and anonymity, the sheer amount of otherwise very useful data you'd have to forbid processing and sharing of is staggering. Take for instance shopping. Should we prevent retailers from collecting transactions data? Should we prevent them from installing CCTVs to deter theft? If neither, then how we're going to prevent them from correlating those two sets to keep a profile on you?
(yes, I know retailers now use credit card data and club cards for that - but say one or both data sets will become unavailable - then they'll start looking for alternatives)
It's a serious question. I don't see reducing data collection as a viable strategy, and I'm not sure if we can present entities from sharing data sets with each other. I'd like to know what could be the long-term privacy perserving strategy that doesn't require us to roll back the computer age.
I don't know if Congress is the solution (http://thehill.com/policy/technology/215457-big-data-lobbyis...), I don't believe any branch of the US government has enough of an understanding with tech issues to pass effective regulation. I hope to be proven wrong though.
The most realistic way, in my opinion, to achieve some degree of reform is by encouraging businesses at a grassroots level to just simply not engage in these kinds of practices. That's an even tougher sell to many businesses than getting Congress to pass a law, but I'm heartened by companies like DuckDuckGo who build a product around the idea of "user privacy above all else". I think if that idea becomes popular enough and new businesses become noble enough to stick to their principals on issues of privacy (vs selling out to make $$) we might have an effective solution.
For what it's worth, members of Congress lack in-depth understanding of most things they legislate. Nobody can know that much about so many topics, almost anything under the Sun (and for NASA legislation, beyond thhe Sun too).
Perhaps we need an IT regulator, who develops expertise. That's how many industries are regulated.
This is something I've been thinking of doing. I don't suppose you've shared these anywhere online by any chance? I always thought that would make a good site - somewhere where you can look up certain services' privacy policies in layman's terms. I suspect a good one already exists.
Now, they've given away my age, birthdate, and where I was born. That's the sort of information that, while private and something I don't give away, they know and give away without thinking.
The government already knows (it's part of your SSN information), and any private company that cares will just make you give that info to them as part of the cost of service. You'll do it too, because you don't want to be unable to drive or have a mortgage.
My original point is that those protections won't apply when just crawling through friends and acquaintances mentioning things.
EDIT:
For another example, consider "Thank God, my friend angersock had a car accident today but only scratched the bumper". That's something I don't want as public knowledge, and that my insurance provider could (theoretically) use to raise my rates.
Colleges use Google Apps (including e-mails), the student body (for the most part) all want to work for Google/Facebook/etc, college culture encourages social media (plenty of clubs almost exclusively do their planning and events on FB) and students look up to the founders of the aforementioned companies, or other non-privacy conscious tech people.
No! Nooooooo! Say it isn't so! The market is a magical infallible oracle of laissez-faire goodness! (That snidely said, the market is absolutely a marvellous thing in precisely the contexts where situations are so complex that centralized control is hopeless and only massively distributed decision making can hope to keep up. Again, context is everything.)
Any day now President Obama is going to propose a new privacy bill of rights that will give you much more control over your personal information.
http://www.politico.com/story/2015/01/online-privacy-bill-wh...
* What good is confidentiality on AT&T, when everyone else still is tracking you (websites, cellular provider, electric utility, car manufacturer, CCTV operators, etc.).
* Should privacy require you to pay every one of those businesses $360/year?
Also, AT&T easily could buy the the information they are forgoing from a third party, and for much less than $360/year/customer.
Is it really paranoïa when this is already the case ?
Google's entire business is based around getting your data and selling it to advertisers. More and more startups and companies offer a "free" service in exchange for your personal data which they sell back. Hekl, half of HN probably already works in a startup whose business model is exactly that.
You have absolutely no say in how your data gets used. You also have no guarantee that AT&T actually respect your choice. Sorry for not being OK with my personal information getting passed through fifty servers around the world for various advertising companies.
In the case of AT&T it's even worse because they have a monopoly on the medium: you don't get to choose where your data passes through when calling someone. At least Internet allows people to run µMatrix, RequestPolicy and others, limiting the amount that gets sent through.